Buffer Overrun in Windows Help and Support Center

Reported October 15, 2003, by Microsoft.




·         Windows 2003

·         Windows XP

·         Windows 2000

·         Windows Me

·         Windows NT Server 4.0, Terminal Server Edition, Service Pack 6a (SP6a)

·         NT Server 4.0 SP6a

·         NT Workstation 4.0 SP6a




A vulnerability in Microsoft Windows Messenger Service can result in the remote execution of arbitrary code on the vulnerable system under the Local System security context. This vulnerability is a result of an unchecked buffer in a file associated with the Help Center Protocol (HCP).




Microsoft has released security bulletin MS03-044, "Buffer Overrun in Windows Help and Support Center Could Lead to System Compromise (825119)," which addresses this vulnerability, and recommends that affected users immediately apply the appropriate patch listed in the bulletin.




Discovered by David Litchfield of Next Generation Security Software Ltd.

Hide comments


  • Allowed HTML tags: <em> <strong> <blockquote> <br> <p>

Plain text

  • No HTML tags allowed.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Lines and paragraphs break automatically.